Shopper Approved Reviews
Shopper Approved Reviews has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Shopper Approved Reviews has a vendor fix available, so running the current release closes it.
All of these findings were reported by kr0d. Shopper Approved Reviews is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-3063Shopper Approved Reviews 2.0 - 2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
Read the full analysisVulnerability Records

Shopper Approved Reviews
Author
shopperapprovedapp
woocommerceAt Shopper Approved, we do two things incredibly well. We help you collect the most reviews possible, and we display those reviews in as many strategic locations as possible – maximizing your brand’s visibility while significantly increasing your search traffic and sales. We are an official Google, Bing, and Walmart partner, and are one of the oldest, largest, and highest-rated online review platforms in the world. There’s everyone else – then there’s Shopper Approved. Here’s why we’re different: Shopper Approved Plugin Features: Collect significantly more reviews with our proprietary 2-step review process Collect Seller, Product & Video Reviews all at once to leverage in multiple ways Display star ratings in both paid and organic search results in Google & Bing Sell your products on Walmart with Product Reviews and star ratings Manage your ratings & reviews from around the web – all in one central location Legal Shopper Approved and the Shopper Approved logo are trademarks of Shopper Approved. Their use is subject to trademark law. Use of this plugin does not grant permission to use the name, logo, or branding without express consent. All code and included assets in this plugin are licensed under the GPL v2 or later.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C